Delegation in role-based access control

被引:62
作者
Crampton, Jason [1 ]
Khambhammettu, Hemanth [1 ]
机构
[1] Royal Holloway Univ London, Informat Secur Grp, London, England
关键词
authorization; delegation; role-based access control; transfer; grant; workflow;
D O I
10.1007/s10207-007-0044-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
User delegation is a mechanism for assigning access rights available to one user to another user. A delegation can either be a grant or transfer operation. Existing work on delegation in the context of role-based access control models has extensively studied grant delegations, but transfer delegations have largely been ignored. This is largely because enforcing transfer delegation policies is more complex than grant delegation policies. This paper, primarily, studies transfer delegations for role-based access control models. We also include grant delegations in our model for completeness. We present various mechanisms that authorize delegations in our model. In particular, we show that the use of administrative scope for authorizing delegations is more efficient than using relations. We also discuss the enforcement and revocation of delegations. Finally, we study delegation in the context of workflow systems. In particular, we demonstrate the application of the administrative scope and administrative domain concepts to control delegation of tasks in worklist-based workflow systems.
引用
收藏
页码:123 / 136
页数:14
相关论文
共 27 条
[1]  
ATLURI V, 2003, P 17 ANN IFIP WG 11, P190
[2]  
ATLURI V, 2005, P 10 ACM S ACC CONTR, P49, DOI DOI 10.1145/1063979.1063990
[3]  
AURA T, 1999, LNCS, V1603, P211
[4]   Framework for role-based delegation models [J].
Barka, E ;
Sandhu, R .
16TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2000, :168-176
[5]  
BARKA E, 2002, THESIS GEORGE MASON
[6]  
Bertino E., 1999, ACM Trans. Inf. Syst. Secur., V2, P65, DOI 10.1145/300830.300837
[7]  
Crampton J., 2003, ACM Transactions on Information and Systems Security, V6, P201, DOI 10.1145/762476.762478
[8]  
Crampton J, 2005, P 12 ACM C COMP COMM, P158
[9]  
Ferraiolo David, 2003, ARTECH H COMP SEC LI
[10]   On the formal definition of separation-of-duty policies and their composition [J].
Gligor, VD ;
Gavrila, SI ;
Ferraiolo, D .
1998 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1998, :172-183